This release is a pre-release and may not be stable for production use.
datasette-turnstile
Protect Datasette paths with Cloudflare Turnstile challenges.
Installation
Install this plugin in the same environment as Datasette.
datasette install datasette-turnstile
Configuration
Configure the plugin in your datasette.yaml:
plugins:
datasette-turnstile:
site_key: "0x4AAAAAAxxxxxxxxxxxxxxx"
secret_key:
$env: TURNSTILE_SECRET_KEY
protected_paths:
- "/admin/*"
- "/-/import-*"
exclude_patterns:
- "*.json"
cookie_max_age: 86400
Configuration options
site_key(required): Your Turnstile site key from the Cloudflare dashboardsecret_key(required): Your Turnstile secret key (supports$envsyntax)protected_paths(required): List of URL patterns to protectexclude_patterns(optional): Patterns to exclude from protection (e.g.,*.json)cookie_max_age(optional): Cookie lifetime in seconds (default: 86400 = 24 hours)cookie_name(optional): Name of the verification cookie (default:ds_turnstile)
URL Pattern Matching
Patterns use simple wildcard matching where * matches any characters:
/admin/*- Protects all paths under/admin//-/import-*- Protects/-/import-csv,/-/import-json, etc./data?*&*&*- Protects/datawith 2+ query string parameters
Use ? in patterns to match against the full URL including query string. Without ?, patterns only match the path.
How It Works
- When a user visits a protected path, they're redirected to
/-/turnstile - The challenge page displays a Cloudflare Turnstile widget
- Upon completing the challenge, the token is verified server-side
- On success, a signed cookie is set and the user is redirected to their original destination
- The cookie remains valid for 24 hours (configurable)
API Requests
For requests with Accept: application/json header, the plugin returns a 403 JSON response instead of redirecting:
{"error": "turnstile_required"}
Use exclude_patterns: ["*.json"] to exclude JSON endpoints from protection entirely.
Development
To set up this plugin locally, first checkout the code:
cd datasette-turnstile
To run the tests:
uv run pytest
Create a config file using Turnstile test keys:
cat > datasette.yaml << 'EOF'
plugins:
datasette-turnstile:
site_key: "1x00000000000000000000AA"
secret_key:
$env: TURNSTILE_SECRET_KEY
protected_paths:
- "/demo/example*
EOF
Create an example database:
sqlite3 demo.db "CREATE TABLE example (id INTEGER PRIMARY KEY, name TEXT);"
Put the secret in an environment variable and run Datasette with the plugin:
TURNSTILE_SECRET_KEY='1x0000000000000000000000000000000AA' uv run datasette -c datasette.yaml demo.db
Release files for datasette-turnstile 0.1a3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| datasette_turnstile-0.1a3.tar.gz | 16.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| datasette_turnstile-0.1a3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 29.5 kB
Release files / datasette_turnstile-0.1a3.tar.gz
| Download URL | datasette_turnstile-0.1a3.tar.gz |
|---|---|
| Size | 16.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f36532fd591bbfca139e93bc65df41b64ba0e635ecd8f9a95802ada9e51a05b9
|
|
BLAKE2b-256 checksum How to use checksums |
80fd6e7d6138b00541225b2c6323e94f19d823c023b5491d98ef86bd58530863
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 8, 2026.
Transparency logRelease files / datasette_turnstile-0.1a3-py3-none-any.whl
| Download URL | datasette_turnstile-0.1a3-py3-none-any.whl |
|---|---|
| Size | 13.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ce5a5c7835a52e8ff4be1e29c89b605e35957ac6afe65c4f6968d6f6b93f3fec
|
|
BLAKE2b-256 checksum How to use checksums |
ce711f4abe145eaf5e5cd70f3a74c3344c6f80e3ab6c08d7ef7c8ef8439f9da1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Apr 8, 2026.
Transparency log